RBI Payment Gateway License in India

Apply for your RBI Payment Gateway License with RegisterKaro. Ensure PCI-DSS and RBI compliance, avoid rejections, and launch your fintech legally with expert-led end-to-end support.

checkEnd-to-End Support for RBI Licensing Process
checkComplete PCI-DSS & Regulatory Compliance
checkExpert-Led Documentation & Application Filing
checkFaster Approvals under PSS Act, 2007
checkTrusted by Thousands of Startups & Payment Platforms
google4.6 out of 5
(6296)
trustpilot4.0 out of 5
(1907)
shieldWhat Sets Us Apart
500+MCA Certified Experts
10,000+Trusted Reviews
2500+Monthly Clients Onboardings
Serving Businesses Across India
shieldWhat Sets Us Apart
500+
MCA Certified Experts
10,000+
Trusted Reviews
2500+
Monthly Clients Onboardings
Serving Businesses Across India

What is a Payment Gateway License in India?

A Payment Gateway License, issued by the Reserve Bank of India (RBI) under Section 5 of the Payment and Settlement Systems (PSS) Act, 2007, is a mandatory authorization for any business that wants to operate a system for processing online payments. This license permits the entity to securely transmit transaction information between the customer, the merchant, and the respective banks.

In simple words, it lets a business offer online payment services by safely connecting buyers and sellers for money transfers. Payment Gateways (PGs) that do not handle funds directly but only provide the underlying technology do not need a Payment Aggregator (PA) license. However, they must partner with an RBI-licensed Payment Aggregator and comply with RBI’s regulations.

Law Governing Payment Gateway License in India

To operate a payment gateway or act as a payment aggregator in India, businesses must comply with regulations set by the RBI and follow key financial, data, and IT laws. These ensure secure transactions, proper customer verification, and protection of sensitive information.

  • Payment and Settlement Systems Act, 2007: Governs and authorizes all payment systems in India under the RBI’s control.
  • RBI Guidelines for Payment Aggregators and Gateways (2020): Mandates licensing, capital norms, and compliance standards for non-bank entities.
  • Information Technology Act, 2000: Ensures the legal validity and security of electronic transactions and records.
  • Prevention of Money Laundering Act (PMLA), 2002: Imposes mandatory KYC and anti-money laundering checks on financial intermediaries.
  • Digital Personal Data Protection (DPDP) Act, 2023: Regulates how personal data is collected, stored, and processed by digital platforms.
  • PCI-DSS Standards (Industry Standard): Requires secure handling and storage of card payment data to prevent breaches.

Benefits of Payment Gateway License in India

A Payment Gateway License in India ensures legal compliance, enhances security, and enables smooth digital transactions. It helps businesses build trust, offer multiple payment options, and expand their market reach.

  • Enhanced Security and Trust: The license mandates PCI-DSS compliance, ensuring you handle user data securely and building credibility with customers and partners.
  • Legal Authority to Operate: The license provides the legal foundation to build and offer advanced payment solutions, including white-label wallets and integrated API platforms.
  • Fraud Screening Tools (FST): Licensed payment gateways offer tools like Card Code Value (CCV), Address Verification Service (AVS), and Card Verification Value (CVV) to detect and prevent fraud, helping secure users' personal and financial data.
  • One-Stop Solution: A payment gateway acts as a single platform that connects different digital tools like shopping carts, e-commerce platforms, and software systems through one simple API integration.
  • Access to the Financial Ecosystem: An RBI license is essential for establishing direct partnerships with multiple banks and card networks, allowing you to offer a wide array of payment options (credit/debit cards, UPI, etc.).
  • Market Expansion Opportunities: The RBI-issued payment gateway license enables businesses to process international payments, helping them grow their reach beyond India and enter global markets.

How Does a Payment Gateway Operate in India?

Once a customer places an order on an online platform, the payment gateway goes through a series of steps to complete the transaction securely and smoothly.

1. Encryption

In the first step, the user's browser encrypts the payment details that need to be sent. The payment gateway then securely transfers this encrypted transaction data to the assigned payment processor.

2. Request for Authorization

Once the payment processor receives the data, it sends it to the relevant card network (like Visa or MasterCard). The card-issuing bank then reviews the transaction and either approves or declines it based on the available balance and other checks.

3. Authorization and Confirmation

If the transaction is approved, the payment gateway receives the authorization from the bank. This is then sent to the merchant’s website to confirm the order and complete the payment process successfully.

4. Fund Settlement

Once the transaction is authorized, funds are settled to the merchant's bank account as per RBI's guidelines, typically within T+1 (next business day) or T+0 (same-day) timelines, depending on the arrangement with the Payment Aggregator or bank.

Payment Gateway vs. Payment Aggregator

In India’s digital payment ecosystem, Payment Gateways (PGs) and Payment Aggregators (PAs) work closely together but serve different roles. Understanding the difference is crucial, especially for businesses planning to enter the fintech or e-commerce space.

FeaturePayment GatewayPayment Aggregator
DefinitionA technology that transfers payment data between the customer, merchant, and banks.A service provider that enables merchants to accept payments without a separate bank account.
RoleActs as a bridge between the merchant’s website/app and the acquiring/issuing bank.Collects payments from customers on behalf of multiple merchants.
License RequirementMust be part of an RBI-authorized Payment System.Requires a specific Payment Aggregator (PA) license from the RBI.
Merchant Account NeededUsually requires a merchant to have their account with acquiring banks.Merchants don’t need to maintain a separate bank account.
Funds HandlingDoes not hold or settle funds directly.Holds and settles funds to merchants after receiving customer payments.
ExamplesRazorpay Gateway, PayU Gateway, CCAvenue GatewayRazorpay, Paytm, Instamojo (when acting as aggregators)
Use CaseIdeal for large businesses with their merchant account.Suitable for small to medium businesses without direct banking integration.
SettlementDoes not handle settlement; handled by banks.Aggregators collect and settle funds to the merchant’s account.
Customer InteractionWorks in the background to securely transfer data.Often interacts directly with customers during payment checkout.

Eligibility Criteria for Obtaining Payment Gateway License

To apply for a Payment Gateway License in India, the applicant must meet the following basic requirements:

  • The company must be registered under the Companies Act, 1956 or 2013.
  • There should be at least 2 members in the company.
  • The company must have a minimum of 2 directors.
  • Valid address proof of the business is required.
  • A detailed 5-year business plan must be prepared and submitted.
  • The company should have a current bank account in its name.
  • A system flow diagram and code testing report from a certified software testing agency must be provided.
  • The company should have a Service Tax Registration Number (now covered under GST).
  • It must follow the PCI DSS (Payment Card Industry Data Security Standard) for data security.

Minimum Net Worth Requirement

To obtain a Payment Aggregator (PA) license from the RBI, entities must meet the following net worth criteria:

  • Initial Net Worth: The applicant must have a minimum net worth of Rs. 15 crores at the time of application.
  • Increased Net Worth within 3 Years: This net worth must be increased to Rs. 25 crores within three years of commencing operations as a licensed Payment Aggregator.

Essential Requirements For Obtaining a License for a Payment Gateway

If you’re a business owner planning to apply for an RBI license to operate a payment gateway in India, here are the important technical and security requirements you need to know:

PCI Audit and Final Certification Process

To become PCI DSS compliant, payment gateway operators must undergo a structured audit process. This involves identifying gaps, mitigating risks, reviewing policies, and completing a final assessment for certification.

  • PCI DSS Scoping and Gap Assessment: Identify areas that don’t meet PCI DSS standards.
  • PCI DSS Risk Assessment: Evaluate and document security risks.
  • PCI DSS Policy & Procedure Review: Review and update all security-related policies and procedures.
  • PCI DSS Final Audit and Certification: Final security audit to confirm compliance.
  • Report Attestation and Issuance: Includes AOC (Attestation of Compliance), ROC (Report on Compliance), and COC (Certificate of Compliance).

Security Testing & Documentation

Security testing ensures the payment system is free from exploitable vulnerabilities. This stage involves assessments, simulations, and documentation.

  • Template Sharing: Use standard templates for reports and documentation.
  • Application Security Testing: Test applications for security vulnerabilities.
  • Secure Code Review: Review the source code for security flaws.
  • ASV Scans: Conduct regular external vulnerability scans on all public-facing IP addresses using a PCI-approved vendor (ASV).
  • Internal Vulnerability Assessment: Regularly scan internal network systems and IPs to identify and remediate vulnerabilities.
  • Penetration Testing (Internal and External): Simulate real-world cyberattacks to evaluate system resilience.
  • External Penetration Testing: Ethical hacking attempts on 5 external IPs to assess public-facing system vulnerabilities.
  • Internal Penetration Testing: Simulated attacks on 10 internal IPs to test internal defenses and detect potential insider threats.
  • Network Architecture Documentation: Prepare a network diagram showing all components.

Security Policies to Maintain

To meet RBI guidelines and ensure secure operations, payment gateway operators must implement the following security policies:

  • Antivirus Policy: Guidelines for deploying and maintaining antivirus software across all systems.
  • Firewall Configuration Policy: Rules for setting up, monitoring, and maintaining firewalls to protect network boundaries.
  • DMZ and Internal Policy: Security controls for systems located in the Demilitarized Zone (DMZ) and internal network zones.
  • Patch Management Policy: Regular updating of all software and operating systems to fix vulnerabilities.
  • Database Access Policy: Strict rules and user roles for accessing and modifying database systems.
  • Asset Inventory Policy: Maintain a detailed and updated inventory of all IT hardware and software assets.
  • Change Control Policy: A documented process to evaluate, approve, and track system and infrastructure changes.
  • Data Retention and Disposal Policy: Define how long data is retained and outline secure data disposal procedures.
  • Physical Security Policy: Measures to prevent unauthorized physical access to data centers, servers, and critical hardware.
  • Data & Access Control Policy: Define and restrict data access based on user roles and job responsibilities.
  • PCI DSS Awareness Training: Regular training for employees to stay updated on PCI DSS compliance requirements.
  • Cyber Security Incident Response Policy: A predefined action plan to identify, respond to, and recover from cybersecurity incidents.
  • Password Policy: Enforce strong password creation rules and periodic password updates.
  • Security Logs and Events Policy: Monitor and maintain logs of system activities, access, and alerts to detect anomalies.

Infrastructure Setup Requirements

A secure and well-maintained IT infrastructure is essential for PCI DSS compliance and ongoing payment operations.

  • Database Hardening: Strengthen database security settings.
  • DMZ & Internal Zone Configuration: Proper setup of external and internal network zones.
  • Operating System (OS) Hardening: Secure the operating systems in use.
  • Central Antivirus Server: Install and manage antivirus from one central server.
  • Regular Patch Updates: Ensure all systems are up-to-date.
  • NTP Server: Set up a server to sync time across systems.
  • Multi-Factor Authentication (MFA) System: Enhance login security with MFA.
  • VPN Setup: Secure remote access using a Virtual Private Network (VPN).
  • File Integrity Monitoring (FIM) Server: Detects changes to files in real-time.
  • Firewall Rules: Define security rules for your firewall settings.

How to Get Your RBI Payment Gateway License in India?

With the rapid growth of digital payments in India, setting up a payment gateway has become a key requirement for businesses dealing in online transactions. However, to legally operate a payment gateway, businesses must first obtain authorization from the Reserve Bank of India (RBI).

The process involves submitting an application under the Payment and Settlement Systems Act, 2007, and fulfilling all regulatory requirements.

Step 1: Submit the Registration Application

The applicant needs to fill out and submit Form A to the Chief General Manager of the Department of Payment & Settlement Systems, either at the RBI’s Central Office in Mumbai or any other designated regional RBI office. This is done as per Section 5(1) of the Payment and Settlement Systems (PSS) Act, 2007.

Step 2: RBI Verifies the Details

The RBI will then check and verify all the information and documents submitted by the applicant. It may also conduct further inquiries if needed to ensure everything is genuine and complete.

Step 3: Fulfill RBI Conditions

To get the license, the applicant must meet all the necessary conditions set by the RBI under Section 7 of the PSS Act, 2007. These include operational, technical, and financial compliance requirements.

Step 4: License Issuance by RBI

If the RBI is satisfied with the application and all conditions are met under Section 7(1) of the Act, it will issue the Authorization Certificate in Form B, officially allowing the business to run a payment gateway system.

Step 5: Application Processing Time

As per Section 7(4) of the PSS Act, 2007, the RBI will process and decide on the application within 6 months from the date of submission.

Documents Needed for Payment Gateway Application

Here is a list of essential documents required to apply for a Payment Gateway License in India:

  • Certificate of Incorporation of the company (under the Companies Act, 1956/2013).
  • PAN Card of the company.
  • Address proof of the registered office (e.g., utility bill, rent agreement).
  • KYC documents of all directors and shareholders (Aadhaar, PAN, Passport, etc.).
  • Board resolution authorizing the application for the license.
  • Memorandum & Articles of Association (MoA & AoA).
  • Business plan for the next 5 years.
  • Bank account details and a cancelled cheque of the company.
  • Code flow diagram and technical system architecture.
  • Code testing report from a certified software testing agency.
  • PCI DSS compliance certificate.
  • Details of payment processing systems and software used.
  • Tax registrations (GST, if applicable).
  • Net worth certificate issued by a certified Chartered Accountant (Minimum ₹15 crore for new applicants, as per RBI norms).
  • Audited financial statements of the company (if available).
  • Grievance redressal mechanism and customer service policies.
  • Information Security Policy, Risk Management Strategy, and Data Privacy Protocols.

Essentials of Payment Gateway System

Here are the key requirements you need to know before setting up a payment gateway system in India:

Components of Payment Gateway System

To run a payment gateway smoothly and legally, certain components must be in place:

  • Merchant Agreement: A Merchant Agreement is a contract between the business and the payment service provider. It outlines the terms for accepting, authorizing, processing, and settling payments.
  • Secure Electronic Transactions (SET): Secure Electronic Transactions are provided by major payment companies like Visa and MasterCard to ensure safe and secure online transactions.

Types of Payment Gateway Providers

Payment gateway services are offered by different types of providers depending on cost, setup, and service level:

  • Second-Party Provider: These are payment gateway providers that offer services with a lower Transaction Discount Rate (TDR), but the overall transaction cost is high.
  • Third-Party Provider: Also called non-bank payment aggregators, these providers have lower setup costs and charge a TDR of around 2% to 4%, making them more affordable for small businesses.

Conditions for Obtaining a Certificate of Authorization For Payment Gateway

Before receiving a Certificate of Authorization under Section 7 of the Payment and Settlement Systems Act, 2007, the applicant must meet the following conditions:

  • There must be a clear need for the proposed payment service or system that the applicant plans to offer.
  • The payment system should follow the technical standards set for its design and operation.
  • The system must include proper terms and conditions, including strong security measures for safe operation.
  • The method of transferring funds within the payment system should be clearly defined and secure.
  • The payment system should have a clear process for settling payment instructions and calculating what each party owes.
  • The financial background, industry experience, and honesty of the company’s management will be evaluated.
  • There must be clear terms and conditions that define the relationship between customers and the payment provider.
  • The system should follow the current credit and monetary policies set by regulatory authorities.
  • A specific time frame must be mentioned for getting the authorization.
  • Any other factors the RBI considers important will also be taken into account.

Costs of Getting a Payment Gateway License

Getting a Payment Gateway License in India includes costs like RBI fees, capital requirements, technology setup, compliance, and consultancy charges.

Here's a quick breakdown:

Cost CategoryDescriptionEstimated Cost (INR)
RBI Application FeesFees paid to the Reserve Bank of India for processing the license application.Rs. 10,000 – Rs. 25,000 (approx.)
Capital Requirement CostsMinimum net worth requirement to be maintained as per RBI norms.Rs. 15 crores (application) Rs. 25 crores (within 3 years)
Technology and Compliance CostsIncludes setting up secure infrastructure, PCI DSS certification, audits, and cybersecurity tools.Rs. 10 lakhs – Rs. 50 lakhs (depending on system complexity)
Professional and Consultancy FeesCharges for legal, financial, and compliance experts assisting with documentation, audits, and filing.Rs. 2 lakhs – Rs. 10 lakhs (or more, based on scope)

Ongoing Compliance and Responsibilities For Payment Gateway

Once a Payment Gateway License is obtained, the license holder must follow several ongoing compliance requirements to maintain the authorization and operate legally:

  • Audits & Certification: Conduct regular RBI and PCI DSS-compliant audits and obtain annual certification from a CERT-IN auditor, ensuring timely renewals.
  • Data Security Compliance: Continuously comply with PCI DSS and other security protocols to protect customer data.
  • Transaction Monitoring: Monitor all transactions for fraud, suspicious activity, and ensure KYC norms are followed.
  • Reporting to RBI: Submit regular reports to the Reserve Bank of India, including financials, operational updates, and security incidents.
  • Maintain Net Worth: Ensure the company’s net worth stays in line with RBI’s minimum requirements (Rs. 15–25 crores).
  • Customer Grievance Redressal: Set up a dedicated system to handle customer complaints and resolve them promptly.
  • Disaster Recovery & Backup: Maintain proper data backup systems and disaster recovery plans to ensure business continuity.

Connect with RegisterKaro and let our experts handle the legal hassle while you grow your business.


Frequently Asked Questions (FAQs)

What is the main law that governs payment gateway licenses in India?

The issuance and regulation of payment gateway licenses are governed under the Payment and Settlement Systems Act, 2007, regulated by the Reserve Bank of India (RBI).

Can a sole proprietorship or partnership get a payment gateway license?

+

What happens if my application is rejected by the RBI?

+

Do I need a payment gateway license for my small e-commerce website?

+

What is PCI-DSS compliance, and why is it mandatory?

+

Can I accept international payments with this license?

+

How is a payment gateway different from a payment processor?

+

What are the penalties for operating without a valid license?

+

How can a consultant help me get the license faster?

+

Why Choose RegisterKaro for Your Payment Gateway License?

Choosing the right partner can make the complex process of obtaining a Payment Gateway License smooth and stress-free. Here’s why RegisterKaro is the preferred choice for many businesses:

  • Expert Guidance: Our team of experts understands RBI’s regulatory framework and ensures your application complies with all legal and technical requirements under the PSS Act, 2007.
  • End-to-End Support: From preparing your business plan and financial reports to submitting Form A and handling RBI correspondence—we manage everything for you.
  • Save Time with Proven Process: With years of experience, we help you navigate around delays and rejections by proactively addressing issues before submission.
  • Transparent and All-Inclusive Packages: No hidden charges—our pricing covers everything from legal drafting to audits, PCI DSS support, and application filing.
  • Dedicated Post-License Compliance Assistance: Our relationship doesn’t end with license approval. We continue to support you with ongoing compliance, annual reporting, audits, and RBI filings.

Why Choose RegisterKaro for Your Payment Gateway License?

What Our Clients Say

Sudip

Sudip

VerifiedVerified

5/5
Others

I recently used Registerkaro for my Private limited company incorporation and had a fantastic experience. Tanvish Nagpal was incredibly helpful throug... Read more

Date Posted-2025-06-20
Dev Patel

Dev Patel

VerifiedVerified

5/5
Others

I recently got my company incorporated through Register Karo and was very happy with their service. The process was smooth from start to finish. Speci... Read more

Date Posted-2025-06-08
Christopher Soans

Christopher Soans

VerifiedVerified

5/5
Others

All the items required for company incorporation we're completed successfully. Though Aashish who handled the account previously did a very bad job, A... Read more

Date Posted-2025-05-05
Raj Kumar1975

Raj Kumar1975

VerifiedVerified

5/5
Others

Satyapriya Tripathi provide excellent support for ROC, GST, Professional Tax, and all compliance-related work. Their quick response, expert guidance,... Read more

Date Posted-2025-03-17
XenohツAnkur (Ankur Rai)

XenohツAnkur (Ankur R...

VerifiedVerified

5/5
Others

Exceptional support for ROC, GST, Professional Tax, and all compliance-related work. Satyapriya Tripathi and the team provide timely responses, expert... Read more

Date Posted-2025-03-17
Deepak Kumar Singh

Deepak Kumar Singh

VerifiedVerified

5/5
Others

Gravixia took services from Register Karo. Its associates are Prompt and proactive. Additionally Anubhav from Register Karo extended himself and prepa... Read more

Date Posted-2025-02-14
Narinder Abrol

Narinder Abrol

VerifiedVerified

5/5
Others

Great experience with Registerkaro! Fast, efficient, and excellent customer service. Special thanks to Kuldeep Pharswan for being patient and helping... Read more

Date Posted-2025-01-24
Amul Shinde

Amul Shinde

VerifiedVerified

5/5
Others

My experience with RegisterKaro was smooth and efficient. Saba was the person who assisted me through the company incorporation process. She was clear... Read more

Date Posted-2024-11-30
Pragya Mehta

Pragya Mehta

VerifiedVerified

5/5
Others

Service and followup was great. I would specially like to thank Shubham for coordinating all formalities needed to incorporate the Company. I will def... Read more

Date Posted-2023-12-28
RS Hari

RS Hari

VerifiedVerified

5/5
Others

Good support! You just pay,share required documents and relax rest they will take care! I should mention the support staff especially Mitushi Jain, sh... Read more

Date Posted-2023-09-19

Latest Blog

View All
whatsapp-icon